CVE-2026-59822CISA KEVEPSS p56.3%
CVE-2026-59822BerriAI LiteLLM Improper Authentication Vulnerability
BerriAI / LiteLLM
Description
BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token.
Scoring
| CVSS | 8.2 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N |
| EPSS | 0.84% probability of exploitation · percentile 56.3% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-03 |
CISA KEV entry
Added to KEV: 2026-09-02